CVE-2026-14456
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/08/2026
Last modified:
28/08/2026
Description
Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes<br />
valid QUIC Initial packets for unknown destination connection IDs, it<br />
can allocate and queue new incoming channels without enforcing any limit.<br />
<br />
Impact summary: A remote peer that can make many Initial packets reach the<br />
server listener faster than the application accepts connections, can cause the<br />
memory allocated to store the per-channel state to grow without any limits,<br />
potentially making the QUIC listener unavailable and causing Denial of Service.<br />
<br />
CWE: CWE-770: Allocation of Resources Without Limits or Throttling<br />
<br />
Description: The function that handles inbound QUIC packets uses<br />
Connection-Id from the packet header to find an existing connection<br />
(QUIC channel). If no existing connection is found and the packet<br />
type is INITIAL, the function treats the packet as a new connection. It<br />
allocates a new channel object and inserts it into a queue where it<br />
waits to be accepted by the local application with SSL_accept(3ossl).<br />
The memory occupied by these initial channel objects may grow<br />
without bounds if the application is not able to call SSL_accept()<br />
frequently enough to serve these inbound connection requests.<br />
<br />
The issue is present since OpenSSL 3.5 when the QUIC server implementation<br />
was added.<br />
<br />
The fix introduces a limit for pending connections. The default limit is set<br />
to 256 pending connections (waiting to be accepted by the local application).<br />
Applications may change the default by calling SSL_set_value_uint(3ossl).<br />
<br />
FIPS impact: no<br />
The FIPS module is not affected as the QUIC implementation is outside of<br />
the OpenSSL FIPS module boundary.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/openssl/openssl/commit/08e7756c3900bcfd77a720e7b74e27d6e4ed01a9
- https://github.com/openssl/openssl/commit/4084152e040329ca0194c4c1750b9b46d00a5b6b
- https://github.com/openssl/openssl/commit/f2f1465f2d2e5c61dfeac4d20fd093797d821139
- https://openssl-library.org/news/secadv/20260813.txt
- http://www.openwall.com/lists/oss-security/2026/08/13/4



